<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.1.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: A bad month for CAPTCHAs</title>
	<link>http://xato.net/bl/2007/12/05/a-bad-month-for-captchas/</link>
	<description>Windows Security Topics by Mark Burnett</description>
	<pubDate>Tue, 13 May 2008 22:40:04 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.1.3</generator>

	<item>
		<title>By: Test</title>
		<link>http://xato.net/bl/2007/12/05/a-bad-month-for-captchas/#comment-1721</link>
		<author>Test</author>
		<pubDate>Thu, 06 Dec 2007 17:16:19 +0000</pubDate>
		<guid>http://xato.net/bl/2007/12/05/a-bad-month-for-captchas/#comment-1721</guid>
					<description>Test :-)</description>
		<content:encoded><![CDATA[<p>Test :-)</p>
]]></content:encoded>
				</item>
	<item>
		<title>By: MustLive</title>
		<link>http://xato.net/bl/2007/12/05/a-bad-month-for-captchas/#comment-1726</link>
		<author>MustLive</author>
		<pubDate>Thu, 06 Dec 2007 18:47:26 +0000</pubDate>
		<guid>http://xato.net/bl/2007/12/05/a-bad-month-for-captchas/#comment-1726</guid>
					<description>&lt;blockquote&gt;In reality, the only function that CAPTCHA on my blog serves is to reduce the number of spam comments&lt;/blockquote&gt;
Mark, your site is about security, so you need reliable captcha. Previous and current one are not reliable enough, so you need more secure captcha.

&lt;blockquote&gt;which I have very much enjoyed following&lt;/blockquote&gt;
I'm glad that you like it. I hope many people, especially security guys and web developers enjoyed my MoBiC project.

&lt;blockquote&gt;On a side note, I decided to change my own CAPTCHA.&lt;/blockquote&gt;
It's good, because previous captcha was very weak, but new one is unsecure too. As you alrady know from my artcile about Cryptographp captcha.

And after I checked today your new captcha (which is using Cryptographp plugin + additional checks) it is vulnerable. This captcha is vulnerable for session reusing with constant captcha
bypass method + bypassing additional protections. I have written you all details in email. So your captcha need to be improved.

&lt;blockquote&gt;The best way to improve on these is to prove me wrong.&lt;/blockquote&gt;
Like I told you, current captcha is unreliable ;-). Man, no need to look for OCR (or cheap work force) when there are holes in captcha. Like I told in Month of Bugs in Captchas using vulnerabilities to bypass captchas is more effective way. So until there are holes in some captcha, it can be reliable.

&lt;blockquote&gt;MustLive, you got any good OCR scripts?&lt;/blockquote&gt;
No, Mark, I have not such scripts. I'm only interesting in a posteriori vulnerabilities (holes in algorithms), not a priori vulnerabilities (holes in idea). So I'm as security auditor interesting only in holes in captchas (others two bypassing methods, OCR and cheap work force, is less interesting for me).</description>
		<content:encoded><![CDATA[<blockquote><p>In reality, the only function that CAPTCHA on my blog serves is to reduce the number of spam comments</p></blockquote>
<p>Mark, your site is about security, so you need reliable captcha. Previous and current one are not reliable enough, so you need more secure captcha.</p>
<blockquote><p>which I have very much enjoyed following</p></blockquote>
<p>I&#8217;m glad that you like it. I hope many people, especially security guys and web developers enjoyed my MoBiC project.</p>
<blockquote><p>On a side note, I decided to change my own CAPTCHA.</p></blockquote>
<p>It&#8217;s good, because previous captcha was very weak, but new one is unsecure too. As you alrady know from my artcile about Cryptographp captcha.</p>
<p>And after I checked today your new captcha (which is using Cryptographp plugin + additional checks) it is vulnerable. This captcha is vulnerable for session reusing with constant captcha<br />
bypass method + bypassing additional protections. I have written you all details in email. So your captcha need to be improved.</p>
<blockquote><p>The best way to improve on these is to prove me wrong.</p></blockquote>
<p>Like I told you, current captcha is unreliable ;-). Man, no need to look for OCR (or cheap work force) when there are holes in captcha. Like I told in Month of Bugs in Captchas using vulnerabilities to bypass captchas is more effective way. So until there are holes in some captcha, it can be reliable.</p>
<blockquote><p>MustLive, you got any good OCR scripts?</p></blockquote>
<p>No, Mark, I have not such scripts. I&#8217;m only interesting in a posteriori vulnerabilities (holes in algorithms), not a priori vulnerabilities (holes in idea). So I&#8217;m as security auditor interesting only in holes in captchas (others two bypassing methods, OCR and cheap work force, is less interesting for me).</p>
]]></content:encoded>
				</item>
</channel>
</rss>
